About Cresset
Cresset is a firm built by clients, for clients. As an independent, award-winning multi-family office and private investment firm, we are reimagining the way wealth is experienced. Our purpose is to help ensure that both wealth and life are fully optimized—integrated, intentional, and aligned with each client’s vision of success.
We provide access to the caliber of talent, ideas, and investment opportunities typically available to the largest single-family offices and institutions. Our approach is personalized, entrepreneurial, and client-first.
Proudly owned by our clients and employees, Cresset was built to endure. We are creating a 100+ year firm—one focused on delivering an exceptional experience, not only for the families we serve but for the team that serves them. Recognized by Barron’s and Forbes among the nation’s top RIA firms, and as one of the industry’s best places to work,* Cresset is guided by long-term relationships, shared success, and a belief that wealth should serve a life well lived.
Job Description
We are seeking an experienced Managing Director, Information Security to lead Cresset's enterprise information security program. This senior technology leadership role is responsible for developing and executing the firm's information security strategy, protecting client and firm information assets, and leading the Information Security team.
Reporting to the Chief Technology Officer, this role partners closely with Technology, Compliance, Legal, HR, and business leaders to strengthen Cresset's security posture while supporting the firm's continued growth and regulatory obligations. The successful candidate combines strong technical expertise with practical leadership and is comfortable balancing security, operational efficiency, and business enablement.
We expect our employees to work in the office three days per week as part of our hybrid work environment.
Key Responsibilities
Security Strategy, Governance & Leadership
-
Develop and execute Cresset's multi-year information security roadmap aligned with the firm's technology strategy and business priorities.
- Maintain the firm's Information Security Program, including security policies, standards, and governance processes.
- Assess the current security environment and develop prioritized plans to strengthen the firm's overall security posture.
- Partner with the CTO, Compliance, Legal, HR, and business leaders to identify, assess, and mitigate cybersecurity risks.
- Lead security architecture and technology decisions supporting cloud, endpoint, network, identity, and data protection capabilities.
- Develop and manage the Information Security budget, vendor relationships, and technology investments in partnership with Technology leadership.
- Provide regular reporting on security initiatives, key risks, and program maturity to executive leadership.
Team Leadership
-
Lead, mentor, and develop the Information Security organization, including leaders responsible for Identity & Access Management (IAM) and Network Security/Data Protection.
- Foster a collaborative, service-oriented security culture that enables the business while appropriately managing risk.
- Establish clear operational processes, performance expectations, and accountability across the Information Security team.
- Provide coaching and career development for security engineers and analysts.
- Manage relationships with security vendors, managed service providers, and consulting partners.
Identity & Access Management
-
Lead the firm's Identity & Access Management (IAM) program, including identity lifecycle management, privileged access management (PAM), single sign-on (SSO), multi-factor authentication (MFA), and identity governance.
- Oversee the evaluation, implementation, and ongoing management of IAM technologies including Okta, SailPoint, CyberArk, Microsoft Entra ID, or similar platforms.
- Ensure effective user provisioning, deprovisioning, access reviews, privileged access controls, and role-based access management.
- Partner with IT, HR, and business leaders to improve onboarding, offboarding, and access governance processes.
Data Protection & Network Security
-
Lead the firm's data protection and network security program to safeguard sensitive client and firm information across cloud, web, email, endpoint, and network environments.
- Oversee Data Loss Prevention (DLP) capabilities, including data classification, policy development, monitoring, and continuous optimization.
- Ensure security controls are integrated across the broader security ecosystem, including CASB, SSE, SIEM, SOAR, EDR, and IAM platforms.
- Monitor key security metrics and continuously improve detection, prevention, and response capabilities.
Regulatory Compliance & Risk Management
-
Partner with Compliance and Legal to ensure the Information Security Program supports applicable regulatory requirements, including SEC Regulation S-P, Regulation S-ID, GLBA, and other relevant cybersecurity and privacy standards.
- Support regulatory examinations, internal audits, and client cybersecurity due diligence activities.
- Lead enterprise cyber risk assessments, data classification initiatives, and third-party cybersecurity risk management.
- Partner with firm leadership to evaluate cyber insurance coverage and overall cyber risk management strategies.
Security Operations & Incident Response
-
Lead the firm's cybersecurity incident response program, including preparation, detection, containment, recovery, and post-incident review.
- Coordinate incident response activities across Technology, Compliance, Legal, Communications, and business stakeholders.
- Conduct periodic tabletop exercises and continuously improve incident response readiness.
- Oversee vulnerability management, endpoint protection, logging and monitoring, penetration testing, and threat detection capabilities.
- Partner with Technology leadership to support business continuity and disaster recovery planning.
Security Culture & Awareness
-
Lead the firm's security awareness and education program, including role-based training for employees.
- Promote a culture of cybersecurity awareness throughout the organization.
- Evaluate emerging technologies and recommend improvements to the firm's overall security program.
- Support client and prospect cybersecurity due diligence requests and represent the Information Security program during security assessments.
Qualifications
Education & Experience
-
Bachelor's degree in Information Security, Computer Science, or a related field; advanced degree preferred.
- 10+ years of progressive information security experience.
- 5+ years leading enterprise information security teams, preferably as a Head of Information Security, Director of Information Security, Senior Director, or similar leadership role.
- Experience building or significantly maturing an enterprise information security program within wealth management, financial services, or another highly regulated industry.
- Demonstrated success developing high-performing teams and managing external vendors and strategic partners.
Technical Expertise
-
Deep understanding of Identity & Access Management, including authentication, authorization, RBAC, PAM, SSO, MFA, and identity governance.
- Experience implementing and managing modern IAM platforms such as SailPoint, Okta, CyberArk, Ping Identity, or Microsoft Entra ID.
- Strong knowledge of cloud security, data protection, DLP technologies, CASB/SSE platforms, SIEM, SOAR, and endpoint security. \
-
Experience securing cloud-first, SaaS-centric environments.
- Strong understanding of cybersecurity and privacy regulations applicable to financial services, including SEC Regulation S-P, Regulation S-ID, GLBA, FFIEC, PCI-DSS, GDPR, and CCPA.
Leadership & Communication
-
Proven ability to develop security strategy, build consensus, and lead organizational change across technical and business stakeholders.
- Strong communication skills with the ability to translate technical risks into business terms for executive leadership and business partners.
- Excellent analytical, problem-solving, and risk-based decision-making skills.
- Demonstrated ability to build trusted relationships across Technology, Compliance, Legal, and business functions.
Preferred Certifications
One or more of the following certifications is strongly preferred:
-
CISSP
- CISM
- CISA
- CRISC
- CCSP
- Or equivalent industry certifications
What We Offer:
At Cresset, we focus on people first. As a service business, our people are our assets. Engaging our clients and employees is our highest priority. Cresset offers a competitive compensation package for the Internship Program. We also offer an opportunity to work in the wealth management environment allowing you to understand the industry and determine if it is the right step for you in your future endeavors. The program includes learning and development activities to give you broader exposure to the company and networking opportunities.
Equal Employment Opportunity
It is the policy of Cresset to ensure equal employment opportunity (EEO) for all employees and applicants for employment without regard to race, color, religion, sex, pregnancy (including childbirth, lactation, or related conditions), national origin or ancestry, age, disability, veteran status, uniformed servicemember status, sexual orientation, gender identity, status as a parent, genetic information (including testing and characteristics), or any other characteristic protected by applicable federal, state, or local law. It is Cresset’s policy to comply with applicable laws concerning the employment of persons with disabilities, including reasonable accommodation for applicants and employees with disabilities.
Everything Starts With Culture.
Our Vision
We exist to optimize wealth and elevate life—giving clients the time, clarity, and trusted partnership to pursue what matters most.
Our Values
- Disclosures related to awards, recognitions, and rankings available here.
Cresset refers to Cresset Capital Management, and all its respective subsidiaries and affiliates. Cresset Asset Management, LLC, also conducts advisory business under the names of Cresset Sports & Entertainment, CH Investment Partners, and Cresset Capital. Cresset provides investment advisory, family office, and other services to individuals, families, and institutional clients. Cresset also provides investment advisory services to investment vehicles investing in private equity, real estate, and other investment opportunities. Cresset Asset Management, LLC is an SEC registered investment advisor. SEC registration does not imply any specific level of skill or training.